Your security is our priority
Your Spinomera account contains your coins and payment methods. Keeping it secure is as important to us as it is to you. This guide covers practical steps you can take right now.
Remember: Spinomera will never ask you for your password. If someone claiming to be from us does, it's a scam.
Use a strong, unique password
A strong password is your first line of defense. Here's what to do:
- Make it long: 12+ characters is ideal; we require at least 8
- Mix it up: use uppercase, lowercase, numbers, and symbols (!@#$)
- Make it random: avoid words from the dictionary, birthdays, or pet names
- Never reuse: if you use the same password on multiple sites and one gets hacked, your Spinomera account is at risk too
Use a password manager: apps like Bitwarden, 1Password, or KeePass generate and store unique passwords for each site. This is the easiest way to stay secure.
Example of a strong password: Tr0pical$Mango2024!. Example of a weak one: password123.
Enable two-factor authentication (2FA)
Two-factor auth (2FA) adds an extra layer of security. Even if someone guesses your password, they still can't access your account without a second code.
How to set up 2FA
- Log in to your Spinomera account
- Go to Settings → Security
- Tap "Enable Two-Factor Authentication"
- Choose your method: authenticator app (recommended) or SMS
- Follow the on-screen instructions to verify
Authenticator app vs. SMS
Authenticator app (more secure): Use Google Authenticator, Microsoft Authenticator, or Authy. You'll get a 6-digit code that changes every 30 seconds. This method cannot be intercepted via SMS phishing.
SMS text (convenient but less secure): We'll text you a code when you log in. This is easier but vulnerable to SIM swapping attacks. Use this only if you can't use an app.
Save your recovery codes: When you set up 2FA, you'll get 10 one-time codes. Write them down or save them somewhere safe. If you lose access to your authenticator, these codes are your backup.
Keep your devices secure
Your password is only as secure as the device you use to enter it.
- Update regularly: enable automatic OS and app updates on all your devices
- Use antivirus: install reputable antivirus software on Windows/Mac
- Secure Wi-Fi: don't log in on public Wi-Fi without a VPN; use your personal mobile hotspot instead
- Lock your device: use a PIN, fingerprint, or face unlock on your phone
- Log out: don't stay logged in on shared or public computers
Spot phishing and scam emails
Phishing emails pretend to be from Spinomera to trick you into revealing your password.
Red flags:
- Urgent language: "Your account will be closed!" or "Verify immediately!"
- Generic greeting: "Dear user" instead of your name
- Suspicious links: hover over links to see the real URL; it should say spinomera.com
- Poor grammar or spelling: professional companies proofread
- Asking for your password: Spinomera will never do this via email
What to do:
If you get a suspicious email claiming to be from us, don't click any links. Instead, log in directly to your account at spinomera.com (type the address yourself, don't click an email link) and check your account status. Or contact our support team.
Your account has been hacked. What now?
If you suspect unauthorized access:
- Change your password immediately (if you can still log in)
- Reset two-factor auth if it's been changed
- Contact support urgently: submit a support ticket or email us with proof of identity
- Review payment methods: check your linked cards and remove any you don't recognize
- Change other accounts: if you used the same password anywhere else, change it now
We'll help you regain control of your account and investigate any unauthorized activity.
Never share these
- Your password — not with anyone, ever
- Your 2FA codes — not with customer support; they should only ask for the code to verify it works
- Your recovery codes — keep these private; they can unlock your account
- Card details in emails — we'll never ask you to send these via email
- Personal details to unverified sources — if someone unsolicited asks for your birthdate or address, it's likely a scam
Spinomera support rule: our team will never ask you for your password or your 2FA code. If they do, it's not us.